10-07-2014 12:57 AM - edited 03-11-2019 09:52 PM
10-07-2014 01:14 AM
Hi,
I had this happen to me some weeks ago when a colleague was replacing some IPS devices connected to a customer ASA firewall.
I would say that the situation is just as you describe. It certainly was in our case. As the physical interface is down the specific route is removed and the default route is used. This in turn builds the xlate which then continues to forward the traffic wrong even though the physical interface has come up. I guess this really only affects UDP traffic as TCP connections would have to be formed again and again if they didnt go through. In our case the customer had problem with the connections from their WLC.
I am not really sure what could be done to correct this. I am wondering if a NAT configuration between INSIDE and TRANSFER would do the trick or would this just be ignored if either of the interfaces were down? If the NAT configuration was matched (even if the traffic is dropped) even though the other interface is down then I guess this should prevent traffic from getting forwarded to external networks.
So maybe a Static Identity NAT from INSIDE to TRANSFER where you essentially configure NAT for the source LAN subnets and NAT them to themselves. This should force traffic coming from TRANSFER towards the LAN subnets to always follow the NAT configurations rather than the routing table.
As I said, I am not sure if the NAT configuration would be ignored if the other interface is down.
- Jouni
EDIT: Typos
05-17-2023 06:14 AM
This may be related to the "timeout floating-conn" setting which now defaults to infinity / 0:00:00 - There is a documentation bug noted under https://bst.cisco.com/bugsearch/bug/CSCtn72626
Changing the timeout floating-conn to something other than a non-zero setting may resolve the concern and allow connections to be rebuilt on the proper interface as dictated by the routing table.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide